Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2608 | phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment of `rust-phonenumber`, this may get triggered by feeding a maliciously crafted phonenumber over the network, specifically the string `.;phone-context=`. Versions `0.3.3+8.13.9` and `0.2.5+8.11.3` contain a patch for this issue. There are no known workarounds. |
Github GHSA |
GHSA-whhr-7f2w-qqj2 | phonenumber panics on parsing crafted RFC3966 inputs |
Tue, 24 Sep 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-24T20:46:54.422Z
Reserved: 2023-09-08T20:57:45.572Z
Link: CVE-2023-42444
Updated: 2024-08-02T19:23:38.765Z
Status : Modified
Published: 2023-09-19T15:15:56.660
Modified: 2024-11-21T08:22:32.527
Link: CVE-2023-42444
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA